← All CVEs

CVE-2025-51567

critical · 9.1

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

9.1
CVSS
0.4%
EPSS (exploit prob.)
34th
EPSS percentile
2026-01-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-89

Affected products

VendorProductAffected versions
jayeshonline_exam_system1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-51567